# Configuring Kibana with SSL; how to define passphrase for the private key?

**URL:** https://discuss.elastic.co/t/configuring-kibana-with-ssl-how-to-define-passphrase-for-the-private-key/2464
**Category:** Kibana
**Created:** [June 11, 2015, 1:11pm UTC](https://discuss.elastic.co/t/configuring-kibana-with-ssl-how-to-define-passphrase-for-the-private-key/2464 "2015-06-11T13:11:53Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Jakauppila](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakauppila/32/44935_2.png) [@Jakauppila](https://discuss.elastic.co/u/Jakauppila)
#### Post date: [June 11, 2015, 1:11pm UTC](https://discuss.elastic.co/t/configuring-kibana-with-ssl-how-to-define-passphrase-for-the-private-key/2464/1 "2015-06-11T13:11:53Z")

</div>

I'm going through the steps of configuring Kibana via kibana.yml to use SSL for the accessing clients:

```
# SSL for outgoing requests from the Kibana Server (PEM formatted)
#ssl_key_file: /path/to/your/server.key
#ssl_cert_file: /path/to/your/server.crt
ssl_cert_file: D:\certs\KibanaCert.crt
ssl_key_file: D:\certs\KibanaCert.pem

```

How do you specify the passphrase for the private key?

---

<div class="post-metadata">

### Author: ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)
#### Post date: [June 17, 2015, 5:28am UTC](https://discuss.elastic.co/t/configuring-kibana-with-ssl-how-to-define-passphrase-for-the-private-key/2464/2 "2015-06-17T05:28:06Z")

</div>

There isn't a way to specify a passphrase. Most people remove the passphrase from their keys using OpenSSL.

```
openssl rsa -in www.key -out new.key
```

---

<div class="post-metadata">

### Author: ![Jakauppila](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakauppila/32/44935_2.png) [@Jakauppila](https://discuss.elastic.co/u/Jakauppila)
#### Post date: [June 17, 2015, 3:10pm UTC](https://discuss.elastic.co/t/configuring-kibana-with-ssl-how-to-define-passphrase-for-the-private-key/2464/3 "2015-06-17T15:10:43Z")

</div>

Yeah, I did that to get it working, but I'm not a fan of it as a long-term solution.

---

<div class="post-metadata">

### Author: ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)
#### Post date: [June 17, 2015, 5:08pm UTC](https://discuss.elastic.co/t/configuring-kibana-with-ssl-how-to-define-passphrase-for-the-private-key/2464/4 "2015-06-17T17:08:27Z")

</div>

What would you prefer for a long term solution?

For systems that need to be automatically started without human intervention the options I know about are:

- Passphraseless SSL Key
- Store passphrase in config and pass as an argument to TLS server (just as insecure as first scenario)
- Prompt user for passphrase (doesn't scale and requires human intervention or requires an expect script with passphrase; which is also insecure)

Thoughts?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 2:17pm UTC](https://discuss.elastic.co/t/configuring-kibana-with-ssl-how-to-define-passphrase-for-the-private-key/2464/5 "2017-07-06T14:17:54Z")

</div>


